Well it’s true that I found a critical vulnerability on WPThemesFree.com. I intended to report this vulnerability though, but never wonder that Mr. David (the owner of WPThemesFree.com) contacted me first on 16 November 2007. Maybe my friend reported to him. I am not sure.
In one of the email he asked me to work for his site security, well actually I am quite happy about that, although I am not sure that I am qualified or not
I’ll try my best though.
In the emails with him, I told him (Mr.David) what were the problems. Thankfully all bugs were fixed. And yesterday I emailed him again and report some bugs, and it’s fixed today. Cheers to him! Cool
And I am now working on another threat.
Thanks
Zoiz
http://zoiz.web.id




[...] http://zoiz.web.id [Read the rest on (it)gossips network: Zoiz] Related PostsWiCrawl , Simple Access Point AuditorBSC’07 : Asia’s Premier Information Security [...]
Yea, congratz. Actually, the owner emailed me, so i send the detail to him.
Thanks anyway bro, hehe.. I heard that you make tons of money from your site
that’s cool!!
Zoiz!
There are many holes at wpthemesfree.com (which I found today, after reading your post). So you need to work hard on security of this site
, which security need to be improved.
Thanks MustLive for noticing
and yeah, i must work hard on it.. so far I just found several XSS, may I seek your advise if there is something that I don’t understand?
Thanks again for passing by, hehehhe
i’ll be glad if i could help you to find another vulnerability on that site. hehe congrats dude .
[...] November 21, 2007 — Website Security Auditor (6) [...]